[go: up one dir, main page]

buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
abucci@bucci.onl
Admin account
@abucci@buc.ci

Search results for tag #infosec

AodeRelay boosted

[?]urlDNA.io :verified: » 🤖 🌐
@urldna@infosec.exchange

Possible Phishing 🎣
on: ⚠️hxxps[:]//t[.]co/ZdZPdKaPB9
🧬 Analysis at: urldna.io/scan/69d91ea73b77500

    AodeRelay boosted

    [?]CTI.FYI » 🤖 🌐
    @CTI_FYI@infosec.exchange

    🚨New ransom group blog post!🚨

    Group name: kairos
    Post title: South Florida Injury Centers
    Info: cti.fyi/groups/kairos.html

      AodeRelay boosted

      [?]TechnoTenshi :verified_trans: :Fire_Lesbian: » 🌐
      @technotenshi@infosec.exchange

      Apple macOS Privacy & Security settings may not reflect real access to protected folders, according to a demonstration by The Eclectic Light Company using a notarized test app called Insent. The author shows an app can regain access to Documents through Open and Save Panel intent even after the Files & Folders toggle is turned off, with testing on macOS Tahoe 26.4 and suspected impact from macOS 13.5 onward. The reported workaround is to reset TCC for the app and restart, although the author later noted MACL persistence may mean access is not fully cleared.

      eclecticlight.co/2026/04/10/wh

        AodeRelay boosted

        [?]TechnoTenshi :verified_trans: :Fire_Lesbian: » 🌐
        @technotenshi@infosec.exchange

        Apple-related court testimony cited by 404 Media says the FBI recovered incoming Signal message content from an iPhone's internal notification storage after the app had been removed. The report says only incoming notifications were captured, not outgoing messages, and no public technical details confirm exactly how the data was extracted. Signal offers a setting to hide message text in notifications, and the article indicates it was apparently not enabled in this case.

        9to5mac.com/2026/04/09/fbi-use

          AodeRelay boosted

          [?]CTI.FYI » 🤖 🌐
          @CTI_FYI@infosec.exchange

          🚨New ransom group blog post!🚨

          Group name: incransom
          Post title: wright-ryan.com
          Info: cti.fyi/groups/incransom.html

            AodeRelay boosted

            [?]Lenny Zeltser » 🌐
            @lennyzeltser@infosec.exchange

            When an AI tool recommends an action and an employee carries it out, audit logs capture a legitimate human decision. The AI's role disappears. Addressing that blind spot takes more than awareness training.

            zeltser.com/ai-influence-aware

              AodeRelay boosted

              [?]Shodan Safari » 🤖 🌐
              @shodansafari@infosec.exchange

              ... [SENSITIVE CONTENT]

              ASN: AS3462
              Location: Taichung, TW
              Added: 2026-04-09T13:58

                AodeRelay boosted

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//guwpkqgd[.]weebly[.]com
                🧬 Analysis at: urldna.io/scan/69d8b5e83b77500

                  AodeRelay boosted

                  [?]mrfoostang 🇨🇦 » 🌐
                  @mrfoostang@foostang.xyz

                  Enought dropped today to get my attention. Catch up if you’re running it.

                    AodeRelay boosted

                    [?]urlDNA.io :verified: » 🤖 🌐
                    @urldna@infosec.exchange

                    Possible Phishing 🎣
                    on: ⚠️hxxps[:]//oxpainexecu[.]weebly[.]com
                    🧬 Analysis at: urldna.io/scan/69d89ff63b77500

                      AodeRelay boosted

                      [?]mrfoostang 🇨🇦 » 🌐
                      @mrfoostang@foostang.xyz

                      Enought #gitlab #cve dropped today to get my attention. Catch up if you’re running it. #infosec

                      AodeRelay boosted

                      [?]Lenny Zeltser » 🌐
                      @lennyzeltser@infosec.exchange

                      A security product becomes harder to displace when each persona finds value in their own view, from SOC analysts to execs to AI agents. Designing for all of them is a stronger advantage than a longer feature list.

                      zeltser.com/designing-for-huma

                        AodeRelay boosted

                        [?]BeyondMachines :verified: » 🤖 🌐
                        @beyondmachines1@infosec.exchange

                        Aetna Reports Data Breaches Affecting Over 11,600 Members Due to Mailing Errors

                        Aetna reported two data breaches affecting 11,663 individuals caused by a mailing distribution error by a business associate that disclosed member information to unauthorized recipients.

                        ****

                        beyondmachines.net/event_detai

                          AodeRelay boosted

                          [?]Shodan Safari » 🤖 🌐
                          @shodansafari@infosec.exchange

                          ... [SENSITIVE CONTENT]

                          ASN: AS51167
                          Location: Düsseldorf, DE
                          Added: 2026-04-09T20:05

                            AodeRelay boosted

                            [?]urlDNA.io :verified: » 🤖 🌐
                            @urldna@infosec.exchange

                            Possible Phishing 🎣
                            on: ⚠️hxxps[:]//breathtaking-intend-971835[.]framer[.]app/
                            🧬 Analysis at: urldna.io/scan/69d8c3e63b77500

                              AodeRelay boosted

                              [?]Ben Rothke » 🌐
                              @benrothke@infosec.exchange

                              My @OneRSAC information security book of the month review: Speak Security With A Business Accent: How to Communicate Cybersecurity Concepts Clearly, Ease Friction with Stakeholders & Influence Decision’ by Joshua Mason. Sage advice for pros. rsaconference.com/library/blog

                                AodeRelay boosted

                                [?]Security Feed » 🤖 🌐
                                @securityfeed@infosec.exchange

                                🔒 Security News Digest - 2026-04-10

                                📊 14 updates from 8 sources:

                                🔹 The Hacker News: GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
                                thehackernews.com/2026/04/glas

                                🔹 darkreading: Industrial Controllers Still Vulnerable As Conflicts Move to Cyber
                                darkreading.com/ics-ot-securit

                                🔹 SecurityWeek: Juniper Networks Patches Dozens of Junos OS Vulnerabilities
                                securityweek.com/juniper-netwo

                                🔹 BleepingComputer: Analysis of one billion CISA KEV remediation records exposes limits of human-scale security
                                bleepingcomputer.com/news/secu

                                🔹 The Record from Recorded Future News: Florida investigates OpenAI for role ChatGPT may have played in deadly shooting
                                therecord.media/florida-invest

                                🔹 Security News | TechCrunch: France to ditch Windows for Linux to reduce reliance on US tech
                                techcrunch.com/2026/04/10/fran

                                🔹 SecurityWeek: In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack
                                securityweek.com/in-other-news

                                🔹 Security Boulevard: [un]prompted 2026 – Anatomy Of An Agentic Personal Al Infrastructure
                                securityboulevard.com/2026/04/

                                🦠 Malwarebytes: ClickFix finds a new way to infect Macs
                                malwarebytes.com/blog/news/202

                                🔹 Security Boulevard: ClickFix finds a new way to infect Macs
                                securityboulevard.com/2026/04/

                                🔹 darkreading: Orange Business Reimagines Enterprise Voice Communications With Trust and AI
                                darkreading.com/endpoint-secur

                                🔹 darkreading: FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats
                                darkreading.com/threat-intelli

                                🔹 BleepingComputer: Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
                                bleepingcomputer.com/news/secu

                                🦠 Malwarebytes: Fake Claude site installs malware that gives attackers access to your computer
                                malwarebytes.com/blog/scams/20

                                  AodeRelay boosted

                                  [?]urlDNA.io :verified: » 🤖 🌐
                                  @urldna@infosec.exchange

                                  Possible Phishing 🎣
                                  on: ⚠️hxxps[:]//instagram-uson[.]vercel[.]app
                                  🧬 Analysis at: urldna.io/scan/69d8d8453b77500

                                    AodeRelay boosted

                                    [?]Ben Rothke » 🌐
                                    @benrothke@infosec.exchange

                                    Built by a veteran team & led by former @google and @Mandiant execs, Mallory AI is a new intelligence platform & now in GA. It’s built for exposure investigation & intel workflows. Important for .
                                    api.cyfluencer.com/s/mallory-g

                                      AodeRelay boosted

                                      [?]AA » 🌐
                                      @AAKL@infosec.exchange

                                      Two wrongs don't make a right. They make multiple wrongs. There's no stopping this train wreck now.

                                      "Anthropic describes Project Glasswing as a coalition of tech giants committing $100 million in AI resources to hunt down and fix long-hidden vulnerabilities in critical open source software that it's finding with its new Mythos AI program. Or as The Reg put it, 'an AI model that can generate zero-day vulnerabilities'."

                                      The Register: Opinion: Project Glasswing and open source software: The good, the bad, and the ugly theregister.com/2026/04/10/pro @theregister @sjvn

                                        AodeRelay boosted

                                        [?]AA » 🌐
                                        @AAKL@infosec.exchange

                                        The Register: CPUID site hijacked to serve malware instead of HWMonitor downloads theregister.com/2026/04/10/cpu @theregister @carlypage

                                          AodeRelay boosted

                                          [?]BeyondMachines :verified: » 🤖 🌐
                                          @beyondmachines1@infosec.exchange

                                          Chevin Fleet Solutions Disconnects FleetWave SaaS Following Cybersecurity Incident

                                          Chevin Fleet Solutions took its FleetWave SaaS platform offline in the UK and US following a cybersecurity incident discovered on April 3, 2026. The company is conducting an investigation with external experts to secure Azure-hosted environments before restoration.

                                          ****

                                          beyondmachines.net/event_detai

                                            AodeRelay boosted

                                            [?]AA » 🌐
                                            @AAKL@infosec.exchange

                                            AodeRelay boosted

                                            [?]urlDNA.io :verified: » 🤖 🌐
                                            @urldna@infosec.exchange

                                            Possible Phishing 🎣
                                            on: ⚠️hxxps[:]//mtcfiber[.]weebly[.]com/
                                            🧬 Analysis at: urldna.io/scan/69d902903b77500

                                              AodeRelay boosted

                                              [?]Shodan Safari » 🤖 🌐
                                              @shodansafari@infosec.exchange

                                              ... [SENSITIVE CONTENT]

                                              ASN: AS4134
                                              Location: Shenzhen, CN
                                              Added: 2026-04-09T14:19

                                                [?]jesterchen42 » 🌐
                                                @jesterchen@social.tchncs.de

                                                Oh my... I just stumbled upon a theoretical question:

                                                If we have a data center in space, what should I tick in my information security and risk assessment regarding "data residency"? And which law does apply and does the answer to this change if the data center should not be geostationary?

                                                Also, how should I assess the risk of Kessler syndrome?

                                                  AodeRelay boosted

                                                  [?]Yazoul - Cybersecurity Alerts » 🤖 🌐
                                                  @Matchbook3469@infosec.exchange

                                                  🚨 New security advisory:

                                                  CVE-2026-1115 affects multiple systems.

                                                  • Impact: Remote code execution or complete system compromise possible
                                                  • Risk: Attackers can gain full control of affected systems
                                                  • Mitigation: Patch immediately or isolate affected systems

                                                  Full breakdown:
                                                  yazoul.net/advisory/cve/cve-20

                                                    AodeRelay boosted

                                                    [?]Jonathan Kamens 86 47 » 🌐
                                                    @jik@federate.social

                                                    RE: flipboard.com/@404media/404-me

                                                    If you think there's any chance that law enforcement might ever be interested in the content of your Signal chats, and you don't want them to have access to them, then setting up disappearing messages is necessary but not sufficient. You also need to go into the Signal settings and either disable notifications completely or set them to show "No name or message" so the content won't be capture and preserved in the phone's notification database.
                                                    ""

                                                      AodeRelay boosted

                                                      [?]AA » 🌐
                                                      @AAKL@infosec.exchange

                                                      😂

                                                      Windows Central: Microsoft says Windows 11's bugs are all "resolved": At least the ones it knows about — and new bugs are impossible to avoid windowscentral.com/microsoft/w @windowscentral

                                                        AodeRelay boosted

                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                        @urldna@infosec.exchange

                                                        Possible Phishing 🎣
                                                        on: ⚠️hxxp[:]//amazon-clone-taupe-xi[.]vercel[.]app
                                                        🧬 Analysis at: urldna.io/scan/69d8d8523b77500

                                                          AodeRelay boosted

                                                          [?]TechNadu » 🌐
                                                          @technadu@infosec.exchange

                                                          Leak vs whistleblower ⚖️
                                                          Federal Bureau of Investigation makes arrest
                                                          Journalist: Seth Harp

                                                          Source: theguardian.com/us-news/2026/a

                                                          💬 Your take?
                                                          🔔 Follow TechNadu

                                                          FBI arrests ex-Fort Bragg employee over alleged classified leak to journalist

                                                          Alt...FBI arrests ex-Fort Bragg employee over alleged classified leak to journalist

                                                            AodeRelay boosted

                                                            [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 » 🌐
                                                            @freya@social.highenergymagic.net

                                                            hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                                                            Please boost for reach, any job offers please DM me.

                                                              AodeRelay boosted

                                                              [?]BeyondMachines :verified: » 🤖 🌐
                                                              @beyondmachines1@infosec.exchange

                                                              IntraCare Healthcare Breach Forces Shutdown and Procedure Defers in New Zealand

                                                              New Zealand healthcare provider IntraCare suffered a cyber breach in March 2026, leading to a total IT shutdown, the theft of patient data, and the postponement of 28 medical procedures.

                                                              ****

                                                              beyondmachines.net/event_detai

                                                                AodeRelay boosted

                                                                [?]Shodan Safari » 🤖 🌐
                                                                @shodansafari@infosec.exchange

                                                                ... [SENSITIVE CONTENT]

                                                                ASN: AS214025
                                                                Location: Fremont, US
                                                                Added: 2026-04-08T23:38

                                                                  AodeRelay boosted

                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                  @urldna@infosec.exchange

                                                                  Possible Phishing 🎣
                                                                  on: ⚠️hxxps[:]//compra-shopee[.]vercel[.]app
                                                                  🧬 Analysis at: urldna.io/scan/69d8a0073b77500

                                                                    AodeRelay boosted

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Nelnet (student loan servicer).

                                                                    8 to 15 characters and no spaces? Why no spaces? Also limited to only these 6 special characters. That could mean that there is some process somewhere that puts this as part of a command line invocation.

                                                                    dumbpasswordrules.com/sites/ne

                                                                      AodeRelay boosted

                                                                      [?]TechNadu » 🌐
                                                                      @technadu@infosec.exchange

                                                                      Deepfake law enforced ⚖️
                                                                      Ted Cruz + Amy Klobuchar
                                                                      First TAKE IT DOWN conviction
                                                                      48hr takedown rule

                                                                      Source: commerce.senate.gov/press/rep/

                                                                      🔔 Follow @technadu

                                                                      Cruz, Klobuchar TAKE IT DOWN Act Leads to Conviction in Case Targeting AI-Generated Deepfakes

                                                                      Alt...Cruz, Klobuchar TAKE IT DOWN Act Leads to Conviction in Case Targeting AI-Generated Deepfakes

                                                                        AodeRelay boosted

                                                                        [?]CTI.FYI » 🤖 🌐
                                                                        @CTI_FYI@infosec.exchange

                                                                        🚨New ransom group blog post!🚨

                                                                        Group name: pear
                                                                        Post title: Arkansas Oral & Maxillofacial Surgeons
                                                                        Info: cti.fyi/groups/pear.html

                                                                          AodeRelay boosted

                                                                          [?]CTI.FYI » 🤖 🌐
                                                                          @CTI_FYI@infosec.exchange

                                                                          🚨New ransom group blog post!🚨

                                                                          Group name: pear
                                                                          Post title: Colonial Presbyterian Church
                                                                          Info: cti.fyi/groups/pear.html

                                                                            AodeRelay boosted

                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                            @urldna@infosec.exchange

                                                                            Possible Phishing 🎣
                                                                            on: ⚠️hxxps[:]//westernuni0ninternationaltransactions[.]weebly[.]com
                                                                            🧬 Analysis at: urldna.io/scan/69d899bb3b77500

                                                                              AodeRelay boosted

                                                                              [?]The Cyber Unc » 🌐
                                                                              @cyberseckyle@infosec.exchange

                                                                              New by me: Microsoft’s WireGuard and VeraCrypt lockout is bigger than a support issue.

                                                                              What stood out to me is not just the headline. It is how quickly a centralized trust and signing pipeline can become a chokepoint for tools people rely on for privacy and security.

                                                                              kylereddoch.me/blog/microsofts

                                                                              Also, shoutout to @cjerrington for putting this on my radar.

                                                                                AodeRelay boosted

                                                                                [?]Patrick » 🌐
                                                                                @ppb1701@ppb.social

                                                                                Proton built their entire brand on one promise: Swiss law means government agencies can't touch your data.
                                                                                Their own Terms of Service, their own infrastructure contracts, and a federal court case from March say otherwise.

                                                                                blog.ppb1701.com/not-even-gove

                                                                                  AodeRelay boosted

                                                                                  [?]CTI.FYI » 🤖 🌐
                                                                                  @CTI_FYI@infosec.exchange

                                                                                  🚨New ransom group blog post!🚨

                                                                                  Group name: akira
                                                                                  Post title: Netgain Networks
                                                                                  Info: cti.fyi/groups/akira.html

                                                                                    AodeRelay boosted

                                                                                    [?]CTI.FYI » 🤖 🌐
                                                                                    @CTI_FYI@infosec.exchange

                                                                                    🚨New ransom group blog post!🚨

                                                                                    Group name: akira
                                                                                    Post title: Turbo International
                                                                                    Info: cti.fyi/groups/akira.html

                                                                                      AodeRelay boosted

                                                                                      [?]BeyondMachines :verified: » 🤖 🌐
                                                                                      @beyondmachines1@infosec.exchange

                                                                                      Credential Exposure Impacts 12 Hungarian Government Ministries

                                                                                      A Bellingcat investigation revealed that nearly 800 Hungarian government credentials from 12 ministries were leaked in breach databases due to poor digital hygiene and infostealer malware.

                                                                                      ****

                                                                                      beyondmachines.net/event_detai

                                                                                        AodeRelay boosted

                                                                                        [?]Shodan Safari » 🤖 🌐
                                                                                        @shodansafari@infosec.exchange

                                                                                        ... [SENSITIVE CONTENT]

                                                                                        ASN: AS61414
                                                                                        Location: Tokyo, JP
                                                                                        Added: 2026-04-09T17:21

                                                                                          AodeRelay boosted

                                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                                          @urldna@infosec.exchange

                                                                                          Possible Phishing 🎣
                                                                                          on: ⚠️hxxps[:]//myvisionsfedcuonlineghvfcuindexphp[.]weebly[.]com
                                                                                          🧬 Analysis at: urldna.io/scan/69d8ae103b77500

                                                                                            AodeRelay boosted

                                                                                            [?]Jiqiang Feng | Innora AI Security » 🌐
                                                                                            @Innora@infosec.exchange

                                                                                            Everything here is reproducible from the Google Play APK with jadx.

                                                                                            APK: com.eg.android.AlipayGphone v10.8.50.7000
                                                                                            SHA-256: 7b56faa5a0de644fd1803e2a002654e0abec45c9d72a1489ea220c04121a7587

                                                                                            IACR ePrint 2026/526
                                                                                            Zenodo: 10.5281/zenodo.19186848
                                                                                            IPFS: QmeWzqWUfHToBTcuPVSfrzxMDiPT6F48M7qtDVXRBHwhHS
                                                                                            github.com/sgInnora/alipay-sec

                                                                                            If you work on Google Play policy review, or if you're a security researcher who can independently verify — please look at this APK.

                                                                                              AodeRelay boosted

                                                                                              [?]TechNadu » 🌐
                                                                                              @technadu@infosec.exchange

                                                                                              9-hour exploit window ⚠️
                                                                                              Marimo RCE → active
                                                                                              Sysdig saw credential theft
                                                                                              Patch fast.

                                                                                              Source: securityweek.com/critical-mari

                                                                                              🔔 Follow @technadu

                                                                                              Critical Marimo Flaw Exploited Hours After Public Disclosure

                                                                                              Alt...Critical Marimo Flaw Exploited Hours After Public Disclosure

                                                                                                AodeRelay boosted

                                                                                                [?]Jiqiang Feng | Innora AI Security » 🌐
                                                                                                @Innora@infosec.exchange

                                                                                                Alipay (100M+ Google Play installs) — what I found by reverse-engineering the APK:

                                                                                                1. A remotely activatable SSL/TLS kill switch
                                                                                                2. 79,371 server-replaceable methods bypassing Play review
                                                                                                3. 1,834 undisclosed data hooks (IMEI, GPS, clipboard, audio)
                                                                                                4. 97% of permission checks return null

                                                                                                Ant Group's response: "these vulnerabilities do not exist."

                                                                                                40 days later, the SSL bypass is still in production.

                                                                                                Thread with code evidence ↓

                                                                                                  AodeRelay boosted

                                                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                  @urldna@infosec.exchange

                                                                                                  Possible Phishing 🎣
                                                                                                  on: ⚠️hxxps[:]//093421tr[.]weebly[.]com
                                                                                                  🧬 Analysis at: urldna.io/scan/69d883ef3b77500

                                                                                                    AodeRelay boosted

                                                                                                    [?]Ev Delen » 🌐
                                                                                                    @evdelen@mstdn.ca

                                                                                                    I get a call from my insurance company basically saying "please give us all your information in order to confirm what we have on file".

                                                                                                    Are you kidding me?

                                                                                                    You call me, out of the blue, and I'm supposed to recite to you ALL of my PERSONAL INFORMATION over an insecure channel like the telephone, where anyone can make up their Caller ID and can represent themselves as whoever they want?

                                                                                                    Holy shit, talk about red flags!

                                                                                                      AodeRelay boosted

                                                                                                      [?]Security Feed » 🤖 🌐
                                                                                                      @securityfeed@infosec.exchange

                                                                                                      🔒 Security News Digest - 2026-04-10

                                                                                                      📊 18 updates from 5 sources:

                                                                                                      🔹 SecurityWeek: MITRE Releases Fight Fraud Framework
                                                                                                      securityweek.com/mitre-release

                                                                                                      🔹 BleepingComputer: Google rolls out Gmail end-to-end encryption on mobile devices
                                                                                                      bleepingcomputer.com/news/goog

                                                                                                      🔹 SecurityWeek: Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000
                                                                                                      securityweek.com/chrome-147-pa

                                                                                                      🔹 The Hacker News: Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
                                                                                                      thehackernews.com/2026/04/brow

                                                                                                      🔹 Security Boulevard: How AI Is Reshaping Wholesale Network Defense
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 Security Boulevard: How Acronis and SuperOps help MSPs work smarter with integrated cyber protection
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 Security Boulevard: How AutoSecT Simplifies Audit Preparation for Global Enterprises
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 Security Boulevard: The Security Gap Hiding in Your Salesforce Org
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 Security Boulevard: Breach of Confidence: 10 April 2026
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 Security Boulevard: When Privacy Laws Force You to Know Too Much: The Perverse Incentives of Age Verification Regimes
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 SecurityWeek: Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
                                                                                                      securityweek.com/orthanc-dicom

                                                                                                      🔹 BleepingComputer: Microsoft: Canadian employees targeted in payroll pirate attacks
                                                                                                      bleepingcomputer.com/news/micr

                                                                                                      🔹 Security Boulevard: Authentication Solutions for Businesses: Benefits, Use Cases, and More
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 Security Boulevard: Best Sentry Alternatives for Error Tracking and Monitoring (2026)
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 Security Boulevard: What Is an LLM Proxy and How Proxies Help Secure AI Models
                                                                                                      securityboulevard.com/2026/04/

                                                                                                      🔹 SecurityWeek: Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday
                                                                                                      securityweek.com/industry-reac

                                                                                                      🔹 The Record from Recorded Future News: UK says it exposed Russian submarine activity near undersea cables
                                                                                                      therecord.media/uk-says-it-exp

                                                                                                      🔹 BleepingComputer: Supply chain attack at CPUID pushes malware with CPU-Z/HWMonitor
                                                                                                      bleepingcomputer.com/news/secu

                                                                                                        AodeRelay boosted

                                                                                                        [?]Infoblox Threat Intel » 🌐
                                                                                                        @InfobloxThreatIntel@infosec.exchange

                                                                                                        From call scripts and scams to command and control—Southeast Asia’s scam centres are levelling up.

                                                                                                        In our latest research with Chong Lua Dao, we track a sophisticated Android banking trojan directly to the K99 Triumph City scam compound in Sihanoukville, Cambodia, and the high-ranking political elites behind it.

                                                                                                        Using a combination of technical analysis, infrastructure patterns, and operational visibility provided by former captives, we were able to map thousands of targeted lure and C2 domains used to distribute and administer the malware across Asia, Africa, Europe, and Latin America.

                                                                                                        What we uncovered is a turnkey malware-as-a-service (MaaS) platform sold to scam-centre based criminal networks, including K99, enabling real-time surveillance, credential theft, biometric data exfiltration, and financial fraud on a global scale. Victims are funnelled through domains impersonating government services, financial institutions, e-commerce platforms and airlines, with new domains registered every month.

                                                                                                        In addition to giving criminal operators complete control over infected devices, behind the malware sits a highly coordinated operation. Our investigation unpacks the whole thing, revealing multiple C2 panels organised by country and “customer” as well as the integration of AI-driven tools used to support attacks targeting victims in at least 21 countries and 15 languages.

                                                                                                        What’s more, we have found that there is significant overlap with the infrastructure and business networks attributed to the DNS threat actors Vigorish Viper and Vault Viper, highlighting the continued evolution of the regional cyber threat landscape.

                                                                                                        👉 Read the full report here: infoblox.com/blog/threat-intel
                                                                                                        👉 We spoke to the Economist to explain how the scam centre threat is shifting: economist.com/interactive/asia

                                                                                                          AodeRelay boosted

                                                                                                          [?]BSidesLuxembourg » 🌐
                                                                                                          @BSidesLuxembourg@infosec.exchange

                                                                                                          🚨 New for BSides Luxembourg 2026! 🚨

                                                                                                          📱🗺️ Navigate the Conference Like a Pro with 𝗛𝗔𝗖𝗞𝗘𝗥 𝗧𝗥𝗔𝗖𝗞𝗘𝗥!

                                                                                                          Keeping up with everything at can be… a challenge 😅

                                                                                                          With 5 stages, 2 dedicated villages, live recordings, activities in the Atrium, and multiple workshops running in parallel—it’s easy to miss something awesome.

                                                                                                          So we’ve made it easier 👇

                                                                                                          The full conference schedule is now available on the Hacker Tracker app, making it simple to:

                                                                                                          📅 Browse all sessions in one place
                                                                                                          ⏰ Track what’s happening in real time
                                                                                                          ⭐ Plan your personal schedule
                                                                                                          📍 Never miss the talks you care about

                                                                                                          👉 Check it out here: lnkd.in/dejd-4xm

                                                                                                            AodeRelay boosted

                                                                                                            [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                            @beyondmachines1@infosec.exchange

                                                                                                            Tulane University Employee Data Breach via Oracle EBS Vulnerability

                                                                                                            Tulane University reports a data breach exposing employee data after the Cl0p ransomware group exploited a zero-day vulnerability in the Oracle E-Business Suite to steal Social Security numbers and banking details.

                                                                                                            ****

                                                                                                            beyondmachines.net/event_detai

                                                                                                              AodeRelay boosted

                                                                                                              [?]Shodan Safari » 🤖 🌐
                                                                                                              @shodansafari@infosec.exchange

                                                                                                              ... [SENSITIVE CONTENT]

                                                                                                              ASN: AS3352
                                                                                                              Location: Rome, IT
                                                                                                              Added: 2026-04-08T16:58

                                                                                                                AodeRelay boosted

                                                                                                                [?]Decoder Loop » 🌐
                                                                                                                @decoderloop@infosec.exchange

                                                                                                                Excited to announce: @cxiao will be speaking at @rustconf in Montréal this year, with the talk "Reverse Engineering Rust Malware in 2026"! sched.co/2KHt7

                                                                                                                The widespread adoption of Rust has not only led to an increase in legitimate Rust software, but also an explosion in malware written in Rust. How are malware reverse engineers tackling Rust malware, in 2026?

                                                                                                                The talk will walk through the analysis of a Rust malware sample, look at the limitations of program analysis and decompilation tools, and discuss the challenges in teaching Rust reverse engineering to malware analysts.

                                                                                                                Get your ticket for RustConf today: rustconf.com/register?utm_sour

                                                                                                                RustConf 2026
Hosted by the Rust Foundation

"Reverse Engineering Rust Malware in 2026"
Breakout Session - Sept. 09

Cindy Xiao
Security Researcher,
Decoder Loop

RustConf 2026 - Montreal + Online
rustconf.com

                                                                                                                Alt...RustConf 2026 Hosted by the Rust Foundation "Reverse Engineering Rust Malware in 2026" Breakout Session - Sept. 09 Cindy Xiao Security Researcher, Decoder Loop RustConf 2026 - Montreal + Online rustconf.com

                                                                                                                  AodeRelay boosted

                                                                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                  @urldna@infosec.exchange

                                                                                                                  Possible Phishing 🎣
                                                                                                                  on: ⚠️hxxps[:]//135461223[.]site/465/7717c2b3-2f3a-4816-a65c-39bf9267f74a/728738
                                                                                                                  🧬 Analysis at: urldna.io/scan/69d8d2043b77500

                                                                                                                    AodeRelay boosted

                                                                                                                    [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 » 🌐
                                                                                                                    @freya@social.highenergymagic.net

                                                                                                                    hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                                                                                                                    Please boost for reach, any job offers please DM me.

                                                                                                                      AodeRelay boosted

                                                                                                                      [?]AA » 🌐
                                                                                                                      @AAKL@infosec.exchange

                                                                                                                      New.

                                                                                                                      "We can't control the pace of AI-driven vulnerability discovery, but we can control how fast we respond."

                                                                                                                      Sophos: The vulnerability flood is here. Here’s what it means – and how to prepare sophos.com/en-us/blog/vulnerab @SophosXOps

                                                                                                                        AodeRelay boosted

                                                                                                                        [?]Lenny Zeltser » 🌐
                                                                                                                        @lennyzeltser@infosec.exchange

                                                                                                                        We invest hours analyzing a security risk, and that effort makes us overvalue the recommendation. An executive who hasn't shared that analysis weighs the same risk differently, and they might be right.

                                                                                                                        zeltser.com/rejected-security-

                                                                                                                          AodeRelay boosted

                                                                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                          @urldna@infosec.exchange

                                                                                                                          Possible Phishing 🎣
                                                                                                                          on: ⚠️hxxps[:]//mailforapps[.]weebly[.]com
                                                                                                                          🧬 Analysis at: urldna.io/scan/69d78e913b77500

                                                                                                                            AodeRelay boosted

                                                                                                                            [?]Security Feed » 🤖 🌐
                                                                                                                            @securityfeed@infosec.exchange

                                                                                                                            🔒 Security News Digest - 2026-04-09

                                                                                                                            📊 15 updates from 5 sources:

                                                                                                                            🔹 Security Boulevard: AI SOC and SIEM Are Being Repriced
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 Security Boulevard: When We Use AI To Ship Fast, Secrets Spread Fast
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 Security Boulevard: The Most Important Cybersecurity Trends in 2026 So Far
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 BleepingComputer: When attackers already have the keys, MFA is just another door to open
                                                                                                                            bleepingcomputer.com/news/secu

                                                                                                                            🔹 Security Boulevard: Trump’s Proposed $707 Million CISA Budget Cut a ‘Gift to Nation-State Actors’
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 Security Boulevard: React2DoS (CVE-2026-23869): When the Flight Protocol Crashes at Takeoff
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 Security Boulevard: LangChain, Langflow, LiteLLM: When AI’s Foundation Code Becomes the Attack Surface
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 Security Boulevard: [un]prompted 2026 – Al Go Beep Boop!
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 The Record from Recorded Future News: Russia accuses former Radio Free Europe journalist of aiding cyberattacks for Ukraine
                                                                                                                            therecord.media/russia-accuses

                                                                                                                            🔹 Security News | TechCrunch: Hacker stole £700,000 from U.K. energy company by redirecting payment
                                                                                                                            techcrunch.com/2026/04/09/hack

                                                                                                                            🔹 Security Boulevard: Aembit IAM for Agentic AI Is Now Generally Available
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 Security Boulevard: The Web Is Full of Traps — and AI Agents Walk Right into Them
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 Security Boulevard: OpenAI Readies Rollout of New Cyber Model as Industry Shifts to Defense
                                                                                                                            securityboulevard.com/2026/04/

                                                                                                                            🔹 BleepingComputer: Smart Slider updates hijacked to push malicious WordPress, Joomla versions
                                                                                                                            bleepingcomputer.com/news/secu

                                                                                                                            🔹 The Hacker News: UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
                                                                                                                            thehackernews.com/2026/04/uat-

                                                                                                                              AodeRelay boosted

                                                                                                                              [?]AA » 🌐
                                                                                                                              @AAKL@infosec.exchange

                                                                                                                              Palo Alto posted several advisories yesterday, if you missed them:

                                                                                                                              - Critical: CVE-2026-0234 Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration security.paloaltonetworks.com/

                                                                                                                              - PAN-SA-2026-0004 Chromium: Monthly Vulnerability Update (April 2026) security.paloaltonetworks.com/

                                                                                                                              - CVE-2026-0233 Autonomous Digital Experience Manager: Improper validation of ADEM certificate security.paloaltonetworks.com/

                                                                                                                                AodeRelay boosted

                                                                                                                                [?]AA » 🌐
                                                                                                                                @AAKL@infosec.exchange

                                                                                                                                New.

                                                                                                                                Kaspersky: The long road to your crypto: ClipBanker and its marathon infection chain securelist.com/clipbanker-malw @Kaspersky

                                                                                                                                  AodeRelay boosted

                                                                                                                                  [?]TechNadu » 🌐
                                                                                                                                  @technadu@infosec.exchange

                                                                                                                                  CISA adds CVE-2026-1340 (Ivanti EPMM) to KEV ⚠️

                                                                                                                                  Active exploitation confirmed
                                                                                                                                  Known vulns = real attack surface
                                                                                                                                  Are KEVs in your patch priority?

                                                                                                                                  Source: cisa.gov/news-events/alerts/20

                                                                                                                                  💬 Engage
                                                                                                                                  🔔 Follow TechNadu

                                                                                                                                  CISA Adds One Known Exploited Vulnerability to Catalog

                                                                                                                                  Alt...CISA Adds One Known Exploited Vulnerability to Catalog

                                                                                                                                    AodeRelay boosted

                                                                                                                                    [?]RootShell » 🤖 🌐
                                                                                                                                    @rootshellonline@infosec.exchange

                                                                                                                                    Daily drop: insights on ransomware, data breaches, and more. Don’t miss today’s playlist. 🔐 youtube.com/playlist?list=PLXq

                                                                                                                                      AodeRelay boosted

                                                                                                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                      @urldna@infosec.exchange

                                                                                                                                      Possible Phishing 🎣
                                                                                                                                      on: ⚠️hxxps[:]//1vfcuonline[.]weebly[.]com
                                                                                                                                      🧬 Analysis at: urldna.io/scan/69d772643b77500

                                                                                                                                        AodeRelay boosted

                                                                                                                                        [?]Shodan Safari » 🤖 🌐
                                                                                                                                        @shodansafari@infosec.exchange

                                                                                                                                        ... [SENSITIVE CONTENT]

                                                                                                                                        ASN: AS6327
                                                                                                                                        Location: Victoria, CA
                                                                                                                                        Added: 2026-04-03T19:47

                                                                                                                                          AodeRelay boosted

                                                                                                                                          [?]AA » 🌐
                                                                                                                                          @AAKL@infosec.exchange

                                                                                                                                          CISA has added two industrial advisories today: cisa.gov/

                                                                                                                                          An Ivanti vulnerability was added yesterday:

                                                                                                                                          CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

                                                                                                                                            AodeRelay boosted

                                                                                                                                            [?]AA » 🌐
                                                                                                                                            @AAKL@infosec.exchange

                                                                                                                                            AodeRelay boosted

                                                                                                                                            [?]AA » 🌐
                                                                                                                                            @AAKL@infosec.exchange

                                                                                                                                            AodeRelay boosted

                                                                                                                                            [?]Boston Security Meetup » 🌐
                                                                                                                                            @BostonSecurityMeetup@infosec.exchange

                                                                                                                                            Big thank you to our hosts Wellington and food and beverage sponsors Plextrac for supporting this month's meetup.

                                                                                                                                            We have two talks again with Emile Delcourt talking on AI Agents Honeypots before after OpenClaw and Eitan Worcel about Security Backlog in the Age of AI.

                                                                                                                                            Still have a chance to RSVP at buff.ly/JrK6hY1

                                                                                                                                              AodeRelay boosted

                                                                                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                              @urldna@infosec.exchange

                                                                                                                                              Possible Phishing 🎣
                                                                                                                                              on: ⚠️hxxps[:]//ahmedsoumri[.]github[.]io/NETFLIX/
                                                                                                                                              🧬 Analysis at: urldna.io/scan/69d7b8ac3b77500

                                                                                                                                                AodeRelay boosted

                                                                                                                                                [?]PLA_906114 » 🌐
                                                                                                                                                @PLA_906114@mastodon.illumos.cafe

                                                                                                                                                One of my first interactions with encryptions was PGP, by Philip Zimmermann

                                                                                                                                                I wanted certain emails to be encrypted with a public private key pair combination

                                                                                                                                                In reading Zimmermann, documentation I noticed that there could be something wrong.

                                                                                                                                                Source code openness and other eyeballs were needed.

                                                                                                                                                ## We got that in openGPG

                                                                                                                                                I've NEVER trusted closed source encryption schemes.

                                                                                                                                                I sometimes also verify if the shadow that's following me is actually mine

                                                                                                                                                @h3artbl33d @Rairii

                                                                                                                                                  AodeRelay boosted

                                                                                                                                                  [?]CTI.FYI » 🤖 🌐
                                                                                                                                                  @CTI_FYI@infosec.exchange

                                                                                                                                                  🚨New ransom group blog post!🚨

                                                                                                                                                  Group name: akira
                                                                                                                                                  Post title: MN Health Insurance Network
                                                                                                                                                  Info: cti.fyi/groups/akira.html

                                                                                                                                                    AodeRelay boosted

                                                                                                                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                    @urldna@infosec.exchange

                                                                                                                                                    Possible Phishing 🎣
                                                                                                                                                    on: ⚠️hxxps[:]//shawsynre1[.]weebly[.]com
                                                                                                                                                    🧬 Analysis at: urldna.io/scan/69d75ca23b77500

                                                                                                                                                      AodeRelay boosted

                                                                                                                                                      [?]Scott Wilson » 🌐
                                                                                                                                                      @scottwilson@infosec.exchange

                                                                                                                                                      ‘Breaking News:’ Water is wet

                                                                                                                                                      Article - “INTERNET-EXPOSED ICS DEVICES RAISE ALARM FOR CRITICAL SECTORS”

                                                                                                                                                      securityaffairs.com/190525/ics

                                                                                                                                                        AodeRelay boosted

                                                                                                                                                        [?]LimaCharlie » 🌐
                                                                                                                                                        @limacharlieio@infosec.exchange

                                                                                                                                                        Most tools that give you deep forensic flexibility weren't built for enterprise scale. And most enterprise tools weren't built by people who actually work incidents.

                                                                                                                                                        John Strand, Owner of Black Hills Information Security, says LimaCharlie is the exception.

                                                                                                                                                        During an active incident, the BHIS SOC can pull the telemetry and data they need quickly, without query caps, unnecessary clicks, or waiting.

                                                                                                                                                        LimaCharlie delivers security as composable, API-first primitives, giving teams full control over how they collect, query, and act on telemetry. All of it normalized to a single JSON format, stored free for a rolling year, and queryable when it matters most.

                                                                                                                                                        Learn more: limacharlie.io

                                                                                                                                                          [?]Christin White » 🌐
                                                                                                                                                          @ChristinWhite@hachyderm.io

                                                                                                                                                          So people, are you actually worried about and Project Glasswing or are you writing it off as yet another AI marketing stunt?

                                                                                                                                                            AodeRelay boosted

                                                                                                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                                                                                                            @dumbpasswordrules@infosec.exchange

                                                                                                                                                            This dumb password rule is from Itaú Bank.

                                                                                                                                                            I know, it's in spanish, let me translate this monstrosity for you.

                                                                                                                                                            - Allowed characters: letters A to Z uppercase or lowercase (ñ is not allowed), number 0 to 9, #, $, %, &, +, -, . :, ;, _.
                                                                                                                                                            - You must use 8 characters.
                                                                                                                                                            - The password must contain at least one letter and at least one number.
                                                                                                                                                            - ...

                                                                                                                                                            dumbpasswordrules.com/sites/it

                                                                                                                                                              AodeRelay boosted

                                                                                                                                                              [?]Dendrobatus Azureus » 🌐
                                                                                                                                                              @dendrobatus_azureus@polymaths.social

                                                                                                                                                              From my perspective not only what you have pointed out, is horrific
                                                                                                                                                              The following DANGEROUS outcome is also looming for everyone globally

                                                                                                                                                              • Inability to buy critical parts for Computing Systems vehicles medical devices because of greed of the manufacturing Triple Cartel

                                                                                                                                                              • LLM crafted Ponzi Schemes

                                                                                                                                                              • Dubious role of USA based companies and proxies

                                                                                                                                                              • Unwilling Supreme Court and regional Court Systems and District Attorneys to hunt down and disable Ponzi Schemes

                                                                                                                                                              • Facilitating US government in all

                                                                                                                                                              This is the housing Ponzi Schemes repeated

                                                                                                                                                              Thank you for your wonderful input
                                                                                                                                                              🦋💙❤️💋#Lobi 💙💕🌹💐💙🦋

                                                                                                                                                              @rl_dane

                                                                                                                                                              #curl #LLM #hallucinated #slop #AI #InfoSec #programming #technology

                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                [?]BSides312 » 🌐
                                                                                                                                                                @bsides312@infosec.exchange

                                                                                                                                                                What if the biggest security gap in your environment isn't some zero-day, it's DNS?
                                                                                                                                                                At BSides312, Matt Scheurer is bringing live demos breaking down how DNS works, why attackers love it, and why most security teams are sleeping on it.
                                                                                                                                                                Easily one of the most versatile protocols; problem in your network? Somehow it always comes back to DNS. Don't sleep on this talk.
                                                                                                                                                                May 16th. Chicago.
                                                                                                                                                                🎟️ bsides312.org

                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                  [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                  @beyondmachines1@infosec.exchange

                                                                                                                                                                  Google Chrome 147 Update Patches 60 Vulnerabilities Including Two Critical WebML Flaws

                                                                                                                                                                  Google Chrome 147 patches 60 vulnerabilities, including two critical memory corruption flaws in the WebML component that could allow remote code execution. The update also addresses numerous high-severity use-after-free and buffer overflow issues across the V8 engine, Blink, and WebRTC.

                                                                                                                                                                  **Once more, a huge patch for Chrome and Chromium based browsers (Edge, Opera, Brave, Vivaldi...). Don't delay this one, it has two critical flaws and a bunch of others. It's only a matter of time before some get exploited. So don't wait. Updating the browser is easy, all your tabs reopen after the patch.**

                                                                                                                                                                  beyondmachines.net/event_detai

                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                    @urldna@infosec.exchange

                                                                                                                                                                    Possible Phishing 🎣
                                                                                                                                                                    on: ⚠️hxxps[:]//amazon-clone-ochre-three[.]vercel[.]app/
                                                                                                                                                                    🧬 Analysis at: urldna.io/scan/69d79ca43b77500

                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                      [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                      @shodansafari@infosec.exchange

                                                                                                                                                                      ... [SENSITIVE CONTENT]

                                                                                                                                                                      ASN: AS3301
                                                                                                                                                                      Location: Malmö, SE
                                                                                                                                                                      Added: 2026-04-03T20:28

                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                        [?]TechNadu » 🌐
                                                                                                                                                                        @technadu@infosec.exchange

                                                                                                                                                                        NHS Scotland subdomains hijacked ⚠️
                                                                                                                                                                        • Adult content + illegal streams hosted
                                                                                                                                                                        • Likely DNS / WordPress compromise
                                                                                                                                                                        • Legacy infrastructure exploited

                                                                                                                                                                        Trust-based attacks are rising 👇

                                                                                                                                                                        technadu.com/nhs-scotland-doma

                                                                                                                                                                        NHS Scotland Domain Breached to Host Adult Content and Illegal Sports Streams, Exposing Infrastructure Vulnerabilities

                                                                                                                                                                        Alt...NHS Scotland Domain Breached to Host Adult Content and Illegal Sports Streams, Exposing Infrastructure Vulnerabilities

                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                          [?]Yazoul - Cybersecurity Alerts » 🤖 🌐
                                                                                                                                                                          @Matchbook3469@infosec.exchange

                                                                                                                                                                          ⛔ New security advisory:

                                                                                                                                                                          CVE-2026-39339 affects multiple systems.

                                                                                                                                                                          • Impact: Remote code execution or complete system compromise possible
                                                                                                                                                                          • Risk: Attackers can gain full control of affected systems
                                                                                                                                                                          • Mitigation: Patch immediately or isolate affected systems

                                                                                                                                                                          Full breakdown:
                                                                                                                                                                          yazoul.net/advisory/cve/cve-20

                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                            [?]Steele Fortress » 🌐
                                                                                                                                                                            @steelefortress@infosec.exchange

                                                                                                                                                                            The average cost of a thorough pre-acquisition cybersecurity assessment for mid-market transactions sits at approximately $125,000, dwarfing the potential returns on investment that can be achieved through breach avoidance, deal price optimization, and regulatory penalty avoidance.

                                                                                                                                                                            Where would what lies hidden in your investment portfolios? priv... break first in your environment?

                                                                                                                                                                            Read more: steelefortress.com/fortress-fe

                                                                                                                                                                            CyberSecurity

                                                                                                                                                                            🎥 Watch Teaser: steelefortress.com/70w5dq

                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                              [?]CTI.FYI » 🤖 🌐
                                                                                                                                                                              @CTI_FYI@infosec.exchange

                                                                                                                                                                              🚨New ransom group blog post!🚨

                                                                                                                                                                              Group name: pear
                                                                                                                                                                              Post title: The McLamb Group, Inc
                                                                                                                                                                              Info: cti.fyi/groups/pear.html

                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                [?]CTI.FYI » 🤖 🌐
                                                                                                                                                                                @CTI_FYI@infosec.exchange

                                                                                                                                                                                🚨New ransom group blog post!🚨

                                                                                                                                                                                Group name: pear
                                                                                                                                                                                Post title: Siegel Lewitter Malkani
                                                                                                                                                                                Info: cti.fyi/groups/pear.html

                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                  [?]CTI.FYI » 🤖 🌐
                                                                                                                                                                                  @CTI_FYI@infosec.exchange

                                                                                                                                                                                  🚨New ransom group blog post!🚨

                                                                                                                                                                                  Group name: pear
                                                                                                                                                                                  Post title: Family Psychological Associates
                                                                                                                                                                                  Info: cti.fyi/groups/pear.html

                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                    [?]CTI.FYI » 🤖 🌐
                                                                                                                                                                                    @CTI_FYI@infosec.exchange

                                                                                                                                                                                    🚨New ransom group blog post!🚨

                                                                                                                                                                                    Group name: pear
                                                                                                                                                                                    Post title: Powell, Powell & Powell, P.A.
                                                                                                                                                                                    Info: cti.fyi/groups/pear.html

                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                      @urldna@infosec.exchange

                                                                                                                                                                                      Possible Phishing 🎣
                                                                                                                                                                                      on: ⚠️hxxps[:]//roblox[.]com[.]ge/communities/5032828635/
                                                                                                                                                                                      🧬 Analysis at: urldna.io/scan/69d7b1173b77500

                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                        [?]CTI.FYI » 🤖 🌐
                                                                                                                                                                                        @CTI_FYI@infosec.exchange

                                                                                                                                                                                        🚨New ransom group blog post!🚨

                                                                                                                                                                                        Group name: akira
                                                                                                                                                                                        Post title: Sehlmann Fensterbau
                                                                                                                                                                                        Info: cti.fyi/groups/akira.html

                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                          [?]CTI.FYI » 🤖 🌐
                                                                                                                                                                                          @CTI_FYI@infosec.exchange

                                                                                                                                                                                          🚨New ransom group blog post!🚨

                                                                                                                                                                                          Group name: akira
                                                                                                                                                                                          Post title: Newman & Marquez
                                                                                                                                                                                          Info: cti.fyi/groups/akira.html

                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                            [?]CTI.FYI » 🤖 🌐
                                                                                                                                                                                            @CTI_FYI@infosec.exchange

                                                                                                                                                                                            🚨New ransom group blog post!🚨

                                                                                                                                                                                            Group name: akira
                                                                                                                                                                                            Post title: ImageMaster
                                                                                                                                                                                            Info: cti.fyi/groups/akira.html

                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                              @urldna@infosec.exchange

                                                                                                                                                                                              Possible Phishing 🎣
                                                                                                                                                                                              on: ⚠️hxxps[:]//ahmedsiddiqui1948-tech[.]github[.]io/Amazon-clone/
                                                                                                                                                                                              🧬 Analysis at: urldna.io/scan/69d7aab63b77500

                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                                                @shodansafari@infosec.exchange

                                                                                                                                                                                                ... [SENSITIVE CONTENT]

                                                                                                                                                                                                ASN: AS11272
                                                                                                                                                                                                Location: Laurel, US
                                                                                                                                                                                                Added: 2026-04-03T19:34

                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                  [?]TechNadu » 🌐
                                                                                                                                                                                                  @technadu@infosec.exchange

                                                                                                                                                                                                  Hack-for-hire cyberespionage targeting journalists & activists
                                                                                                                                                                                                  • iCloud phishing → Apple ID compromise
                                                                                                                                                                                                  • Android spyware (ProSpy) in trusted apps
                                                                                                                                                                                                  • Linked to BITTER APT ecosystem
                                                                                                                                                                                                  Rising threat of commercial surveillance 👇

                                                                                                                                                                                                  technadu.com/hackers-hired-to-

                                                                                                                                                                                                  Hackers Hired to Target Android, iCloud of Egyptian, Lebanese Journalists and Activists

                                                                                                                                                                                                  Alt...Hackers Hired to Target Android, iCloud of Egyptian, Lebanese Journalists and Activists

                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                    [?]Security Feed » 🤖 🌐
                                                                                                                                                                                                    @securityfeed@infosec.exchange

                                                                                                                                                                                                    🔒 Security News Digest - 2026-04-09

                                                                                                                                                                                                    📊 28 updates from 6 sources:

                                                                                                                                                                                                    🔹 BleepingComputer: Hackers exploiting Acrobat Reader zero-day flaw since December
                                                                                                                                                                                                    bleepingcomputer.com/news/secu

                                                                                                                                                                                                    🦠 Malwarebytes: This fake Windows support website delivers password-stealing malware
                                                                                                                                                                                                    malwarebytes.com/blog/scams/20

                                                                                                                                                                                                    🔹 SecurityWeek: Google Warns of New Campaign Targeting BPOs to Steal Corporate Data
                                                                                                                                                                                                    securityweek.com/google-warns-

                                                                                                                                                                                                    🦠 Malwarebytes: 30,000 private Facebook images allegedly downloaded by Meta employee
                                                                                                                                                                                                    malwarebytes.com/blog/data-bre

                                                                                                                                                                                                    🔹 BleepingComputer: Eurail says December data breach impacts 300,000 individuals
                                                                                                                                                                                                    bleepingcomputer.com/news/secu

                                                                                                                                                                                                    🔹 The Hacker News: Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region
                                                                                                                                                                                                    thehackernews.com/2026/04/bitt

                                                                                                                                                                                                    🔹 Security Boulevard: On Microsoft’s Lousy Cloud Security
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 SecurityWeek: The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security
                                                                                                                                                                                                    securityweek.com/the-hidden-ro

                                                                                                                                                                                                    🦠 Malwarebytes: NSFW app leak exposes 70,000 prompts linked to individual users
                                                                                                                                                                                                    malwarebytes.com/blog/news/202

                                                                                                                                                                                                    🔹 Security Boulevard: NSFW app leak exposes 70,000 prompts linked to individual users
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 Security Boulevard: NSFW app leak exposes 70,000 prompts linked to individual users
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 Security Boulevard: The Cybersecurity Readiness Gap: Why 90% of Companies Are Still Unprepared in 2026
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 The Hacker News: Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
                                                                                                                                                                                                    thehackernews.com/2026/04/adob

                                                                                                                                                                                                    🔹 The Hacker News: The Hidden Security Risks of Shadow AI in Enterprises
                                                                                                                                                                                                    thehackernews.com/2026/04/the-

                                                                                                                                                                                                    🔹 Security Boulevard: The Identity Gap Blocking Agentic AI at Scale
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 SecurityWeek: Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities
                                                                                                                                                                                                    securityweek.com/palo-alto-net

                                                                                                                                                                                                    🔹 Security Boulevard: Why Web Content Filtering Software for Schools Must Go Beyond Simple Blocking
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 The Record from Recorded Future News: Cryptocurrency ATM giant Bitcoin Depot reports $3.6 million stolen in cyberattack
                                                                                                                                                                                                    therecord.media/crypto-atm-bit

                                                                                                                                                                                                    🔹 Security Boulevard: Securing the AI Supply Chain: What are the Risks and Where to Start?
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 BleepingComputer: Webinar: From noise to signal - What threat actors are targeting next
                                                                                                                                                                                                    bleepingcomputer.com/news/secu

                                                                                                                                                                                                    🔹 Security Boulevard: Turning Email Authentication into a Revenue Engine: Why Australian MSPs Can’t Afford to Ignore DMARC-as-a-Service
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 SecurityWeek: Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access
                                                                                                                                                                                                    securityweek.com/google-api-ke

                                                                                                                                                                                                    🔹 The Hacker News: ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
                                                                                                                                                                                                    thehackernews.com/2026/04/thre

                                                                                                                                                                                                    🔹 Security Boulevard: Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🦠 Malwarebytes: Scammers pose as Amazon support to steal your account
                                                                                                                                                                                                    malwarebytes.com/blog/news/202

                                                                                                                                                                                                    🔹 Security Boulevard: The EU AI Act Data Requirements Explained | Kovrr
                                                                                                                                                                                                    securityboulevard.com/2026/04/

                                                                                                                                                                                                    🔹 SecurityWeek: Can we Trust AI? No – But Eventually We Must
                                                                                                                                                                                                    securityweek.com/can-we-trust-

                                                                                                                                                                                                    🔹 SecurityWeek: Apple Intelligence AI Guardrails Bypassed in New Attack
                                                                                                                                                                                                    securityweek.com/apple-intelli

                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                      [?]ANY.RUN » 🌐
                                                                                                                                                                                                      @anyrun_app@infosec.exchange

                                                                                                                                                                                                      🇩🇪 Germany’s critical industries are under active attack.

                                                                                                                                                                                                      We show how SOCs can track key threats hitting finance, healthcare, IT, telecom, and manufacturing right now.

                                                                                                                                                                                                      Discover how to prevent downtime, fraud, and account takeover 👇
                                                                                                                                                                                                      any.run/cybersecurity-blog/ger

                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                        @urldna@infosec.exchange

                                                                                                                                                                                                        Possible Phishing 🎣
                                                                                                                                                                                                        on: ⚠️hxxps[:]//onlinestlouiscommunitycu[.]weebly[.]com
                                                                                                                                                                                                        🧬 Analysis at: urldna.io/scan/69d780ab3b77500

                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                          [?]Lockdownyourlife » 🌐
                                                                                                                                                                                                          @Lockdownyourlife@infosec.exchange

                                                                                                                                                                                                          Good morning. Working on a DV request for groceries this week. We're at $25/$150 if you'd like to support. Please RT for reach! Thanks so much.😍

                                                                                                                                                                                                          C: $Lockdownyourlife
                                                                                                                                                                                                          V: lockdownyourlife
                                                                                                                                                                                                          ko-fi.com/lockdownyourlife

                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                            [?]WIGGWIGG » 🌐
                                                                                                                                                                                                            @wiggwigg@infosec.exchange

                                                                                                                                                                                                            3 months of closed beta with 30 people. The regulatory process required to launch WIGGWIGG gave us the time to accelerate features we'd planned for later.

                                                                                                                                                                                                            The web application is still the main product, but the mobile application is officially on the roadmap to complement it. (1/2)

                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                              [?]Dendrobatus Azureus » 🌐
                                                                                                                                                                                                              @dendrobatus_azureus@polymaths.social

                                                                                                                                                                                                              Does this mean that you shall also stop using curl?

                                                                                                                                                                                                              AFAIK Daniel doesn't care what is used to find bugs

                                                                                                                                                                                                              @rl_dane

                                                                                                                                                                                                              https://mastodon.social/@bagder/116373716541500315

                                                                                                                                                                                                              #curl #LLM #hallucinated #slop #AI #InfoSec #programming #technology

                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                [?]OWASP Foundation » 🌐
                                                                                                                                                                                                                @owasp@infosec.exchange

                                                                                                                                                                                                                Join OWASP Global AppSec EU 2026 in Vienna, June 22–26, for hands-on training, epic talks, and networking with the best community vibes! 🚀

                                                                                                                                                                                                                Secure your spot 👉 owasp.glueup.com/event/owasp-g

                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                  [?]Scott Wilson » 🌐
                                                                                                                                                                                                                  @scottwilson@infosec.exchange

                                                                                                                                                                                                                  Disclaimer: Propaganda alert!
                                                                                                                                                                                                                  Disclaimer: IBM is my employer

                                                                                                                                                                                                                  IBM has published their "2026 Guide to AI Agents".

                                                                                                                                                                                                                  Now, I'm not any kind of fan of , but as several of my friends here have said, we in can't simply ignore AI because some organizations are going to use it, so we need to be able to secure it.

                                                                                                                                                                                                                  In that spirit, I share this web page as an resource.

                                                                                                                                                                                                                  ibm.com/think/topics/ai-agents

                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                    [?]The Spamhaus Project » 🌐
                                                                                                                                                                                                                    @spamhaus@infosec.exchange

                                                                                                                                                                                                                    💪 Contributor "mugufinder" has shared 2,731 domains over the past 30 days 🔥 That’s a +1,969% increase, landing them in the Top10 on the domain leaderboard! Incredible work!

                                                                                                                                                                                                                    Your ongoing support and submissions are what keep the threat intelligence flowing, thank you. ❤️🙏

                                                                                                                                                                                                                    Got malicious or suspicious IPs, domains, URLs, or raw source to share?

                                                                                                                                                                                                                    👉 Join the fight against cybercrime: submit.spamhaus.org/submit/

                                                                                                                                                                                                                    % Monthly change in domains shared
Domain leaderboard
#6 | mugufinder | 2,731 domains

                                                                                                                                                                                                                    Alt...% Monthly change in domains shared Domain leaderboard #6 | mugufinder | 2,731 domains

                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                      [?]FIRST.org » 🌐
                                                                                                                                                                                                                      @firstdotorg@infosec.exchange

                                                                                                                                                                                                                      What if the key to better vulnerability management isn't just patching faster, but understanding why vulnerabilities keep coming back? 🔍

                                                                                                                                                                                                                      Help Net Security connected with speaker Alec Summers, MITRE CVE/CWE Project Lead, Principal Cybersecurity Engineer, and FIRST Member, to explore how CWE mapping is becoming a strategic layer of the vulnerability management stack.

                                                                                                                                                                                                                      🎤 Catch Alec's upcoming presentations at VulnCon26 next week and read the full Q&A here: go.first.org/BZzAf


                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                        [?]Solomon » 🌐
                                                                                                                                                                                                                        @solomonneas@infosec.exchange

                                                                                                                                                                                                                        Anthropic built a model strong enough at vulnerability research that it chose not to release it publicly. Mythos Preview is gated behind an invite-only defensive security program. It reportedly found thousands of zero-days including a 27-year-old OpenBSD bug and chained Linux kernel exploits to full system compromise. What this means for security teams and CTI.

                                                                                                                                                                                                                        solomonneas.dev/blog/anthropic

                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                          [?]Solomon » 🌐
                                                                                                                                                                                                                          @solomonneas@infosec.exchange

                                                                                                                                                                                                                          🔴 Adobe Reader zero-day exploited via malicious PDFs since Dec.
                                                                                                                                                                                                                          🔴 Ivanti EPMM CVE-2026-1340 added to KEV after active RCE exploitation.
                                                                                                                                                                                                                          🟡 APT28 hijacked router DNS on 18,000+ devices to steal Microsoft 365 tokens.
                                                                                                                                                                                                                          solomonneas.dev/intel

                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                            [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                                                                            @shodansafari@infosec.exchange

                                                                                                                                                                                                                            ... [SENSITIVE CONTENT]

                                                                                                                                                                                                                            ASN: AS2518
                                                                                                                                                                                                                            Location: Chiba, JP
                                                                                                                                                                                                                            Added: 2026-04-03T21:19

                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                              @urldna@infosec.exchange

                                                                                                                                                                                                                              Possible Phishing 🎣
                                                                                                                                                                                                                              on: ⚠️hxxps[:]//docs[.]google[.]com/drawings/d/1kJUO4o5XHCN1aVRTQZ_pRyPXlJSl9uFTz-DvYua6FHA/edit
                                                                                                                                                                                                                              🧬 Analysis at: urldna.io/scan/69d7247a3b77500

                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                @rysiek@mstdn.social

                                                                                                                                                                                                                                Oh boy…
                                                                                                                                                                                                                                edition.cnn.com/2026/04/08/chi

                                                                                                                                                                                                                                > A [cyberthreat actor] has allegedly stolen a massive trove of sensitive data – including highly classified defense documents and missile schematics – from a state-run Chinese supercomputer

                                                                                                                                                                                                                                > The dataset, which allegedly contains more than 10 petabytes of sensitive information, is believed by experts to have been obtained from the National Supercomputing Center (NSCC) in Tianjin

                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                  [?]Kemotep :de_gouges:🔰 » 🌐
                                                                                                                                                                                                                                  @kemotep@mastodo.neoliber.al

                                                                                                                                                                                                                                  What is considered state of the art for Endpoint management, and specifically security controls (EDR, SIEM, RMM, etc.) for BSD? There usually exists clients and agents for Linux in this space. There is an abandoned(?) Wazuh port for FreeBSD that I am aware of but I would like to know what people do.

                                                                                                                                                                                                                                  Essentially how does one manage and monitor the security of 100’s or 1,000’s of BSD endpoints like a Windows or Linux or even Mac environment would?

                                                                                                                                                                                                                                    [?]Dissent Doe :cupofcoffee: » 🌐
                                                                                                                                                                                                                                    @PogoWasRight@infosec.exchange

                                                                                                                                                                                                                                    If you were or are a federal employee or are a family member of one, you might want to read this and share it with others who might be concerned:

                                                                                                                                                                                                                                    Trump’s Personnel Agency Is Asking for Federal Workers’ Medical Records

                                                                                                                                                                                                                                    kffhealthnews.org/news/article

                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                      [?]Tara 🕷️:blobbat: » 🌐
                                                                                                                                                                                                                                      @tarajdactyl@anarres.family

                                                                                                                                                                                                                                      :boosts_ok_gay:

                                                                                                                                                                                                                                      attention anybody with substantial experience with Rust and networking: my team is hiring!!

                                                                                                                                                                                                                                      one of few rust jobs I'm aware of that is not web 3.0 horseplop.

                                                                                                                                                                                                                                      fully remote (US timezones), good culture, good trans-inclusive healthcare, good work/life balance, and a nice defensive cybersecurity mission i can get behind.

                                                                                                                                                                                                                                      feel free to reach out for more details and the job posting.

                                                                                                                                                                                                                                      :boosts_ok_gay:

                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                        [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                                                                                        @shodansafari@infosec.exchange

                                                                                                                                                                                                                                        ... [SENSITIVE CONTENT]

                                                                                                                                                                                                                                        ASN: AS4713
                                                                                                                                                                                                                                        Location: Osaka, JP
                                                                                                                                                                                                                                        Added: 2026-04-03T19:34

                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                                          @urldna@infosec.exchange

                                                                                                                                                                                                                                          Possible Phishing 🎣
                                                                                                                                                                                                                                          on: ⚠️hxxps[:]//returnersres[.]weebly[.]com
                                                                                                                                                                                                                                          🧬 Analysis at: urldna.io/scan/69d66d9d3b77500

                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                                            @urldna@infosec.exchange

                                                                                                                                                                                                                                            Possible Phishing 🎣
                                                                                                                                                                                                                                            on: ⚠️hxxps[:]//robiox[.]com[.]af/users/2664643693/profile
                                                                                                                                                                                                                                            🧬 Analysis at: urldna.io/scan/69d6a5bc3b77500

                                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                                              [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 » 🌐
                                                                                                                                                                                                                                              @freya@social.highenergymagic.net

                                                                                                                                                                                                                                              hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net.

                                                                                                                                                                                                                                              Please boost for reach, any job offers please DM me.

                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                                                @urldna@infosec.exchange

                                                                                                                                                                                                                                                Possible Phishing 🎣
                                                                                                                                                                                                                                                on: ⚠️hxxps[:]//btnewmailser[.]weebly[.]com
                                                                                                                                                                                                                                                🧬 Analysis at: urldna.io/scan/69d689b33b77500

                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                  [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                                                                                                  @shodansafari@infosec.exchange

                                                                                                                                                                                                                                                  ... [SENSITIVE CONTENT]

                                                                                                                                                                                                                                                  ASN: AS7511
                                                                                                                                                                                                                                                  Location: Kagoshima, JP
                                                                                                                                                                                                                                                  Added: 2026-04-03T19:40

                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                    [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                    @jik@federate.social

                                                                                                                                                                                                                                                    locks account that maintainer uses to sign bootloaders with no explanation or route for appeal. If they don't fix this, in a few months every Windows computer that uses VeraCrypt whole-disk encryption will stop being able to boot and all the data on it that isn't backed up elsewhere will be lost. 🤦
                                                                                                                                                                                                                                                    If this doesn't convince you big tech has too much control, I don't know what will.
                                                                                                                                                                                                                                                    h/t @zackwhittaker
                                                                                                                                                                                                                                                    techcrunch.com/2026/04/08/vera

                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                      [?]AA » 🌐
                                                                                                                                                                                                                                                      @AAKL@infosec.exchange

                                                                                                                                                                                                                                                      The Register: Microsoft calls time on ASP.NET Core 2.3 on .NET Framework theregister.com/2026/04/08/asp

                                                                                                                                                                                                                                                      From yesterday:

                                                                                                                                                                                                                                                      Hundreds of orgs compromised daily in Microsoft device code phishing attacks theregister.com/2026/04/07/mic @theregister

                                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                                                        @urldna@infosec.exchange

                                                                                                                                                                                                                                                        Possible Phishing 🎣
                                                                                                                                                                                                                                                        on: ⚠️hxxps[:]//att53[.]weebly[.]com
                                                                                                                                                                                                                                                        🧬 Analysis at: urldna.io/scan/69d659333b77500

                                                                                                                                                                                                                                                          Back to top - More...